<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:07:34 +0000</lastBuildDate>
    <item>
      <title>BREW-duplicity-CVE-2019-14853 — ecdsa Denial of Service vulnerability in signature verification and signature malleability</title>
      <link>https://cve.radiocsirt.org/vuln/brew-duplicity-cve-2019-14853</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: duplicity&lt;/p&gt;
&lt;p&gt;## possible DoS in signature verification and signature malleability&lt;/p&gt;
&lt;p&gt;### Impact
Code using `VerifyingKey.verify()` and `VerifyingKey.verify_digest()` may receive exceptions other than the documented `BadSignatureError` when signatures are malformed. If those other exceptions are not caught, they may lead to program termination and thus Denial of Service&lt;/p&gt;
&lt;p&gt;Code using `VerifyingKey.verify()` and `VerifyingKey.verify_digest()` with `sigdecode` option using `ecdsa.util.sigdecode_der` will accept signatures even if they are not properly formatted DER. This makes the signatures malleable. It impacts only applications that later sign the signatures or verify signatures of signatures, e.g. Bitcoin.&lt;/p&gt;
&lt;p&gt;All versions between 0.5 and 0.13.2 (inclusive) are thought to be vulnerable. Code before 0.5 may be vulnerable but didn&amp;#39;t receive extended analysis to rule this issue out.&lt;/p&gt;
&lt;p&gt;### Patches
The patches have been merged to `master` branch in https://github.com/warner/python-ecdsa/pull/115.
The backported patches for a release in the 0.13 branch are in https://github.com/warner/python-ecdsa/pull/124&lt;/p&gt;
&lt;p&gt;They are part of the 0.13.3 release.&lt;/p&gt;
&lt;p&gt;There are no plans to backport them to earlier releases.&lt;/p&gt;
&lt;p&gt;### Workarounds
It may be possible to prevent the Denial of Service by catching also `UnexpectedDER`, `IndexError` and `AssertionError` exceptions. That list hasn&amp;#39;t been verified to be complete though. If those exceptions are raised, the signature verification process should consider the signature to b…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: duplicity&lt;/p&gt;
&lt;p&gt;## possible DoS in signature verification and signature malleability&lt;/p&gt;
&lt;p&gt;### Impact
Code using `VerifyingKey.verify()` and `VerifyingKey.verify_digest()` may receive exceptions other than the documented `BadSignatureError` when signatures are malformed. If those other exceptions are not caught, they may lead to program termination and thus Denial of Service&lt;/p&gt;
&lt;p&gt;Code using `VerifyingKey.verify()` and `VerifyingKey.verify_digest()` with `sigdecode` option using `ecdsa.util.sigdecode_der` will accept signatures even if they are not properly formatted DER. This makes the signatures malleable. It impacts only applications that later sign the signatures or verify signatures of signatures, e.g. Bitcoin.&lt;/p&gt;
&lt;p&gt;All versions between 0.5 and 0.13.2 (inclusive) are thought to be vulnerable. Code before 0.5 may be vulnerable but didn&amp;#39;t receive extended analysis to rule this issue out.&lt;/p&gt;
&lt;p&gt;### Patches
The patches have been merged to `master` branch in https://github.com/warner/python-ecdsa/pull/115.
The backported patches for a release in the 0.13 branch are in https://github.com/warner/python-ecdsa/pull/124&lt;/p&gt;
&lt;p&gt;They are part of the 0.13.3 release.&lt;/p&gt;
&lt;p&gt;There are no plans to backport them to earlier releases.&lt;/p&gt;
&lt;p&gt;### Workarounds
It may be possible to prevent the Denial of Service by catching also `UnexpectedDER`, `IndexError` and `AssertionError` exceptions. That list hasn&amp;#39;t been verified to be complete though. If those exceptions are raised, the signature verification process should consider the signature to b…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-duplicity-cve-2019-14853</guid>
    </item>
    <item>
      <title>CVE-2019-14853</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2019-14853</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; [UNKNOWN] python-ecdsa&lt;/p&gt;
&lt;p&gt;An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; [UNKNOWN] python-ecdsa&lt;/p&gt;
&lt;p&gt;An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2019-14853</guid>
    </item>
    <item>
      <title>Withdrawn: GHSA-2mrj-435v-c2cr — Duplicate Advisory: possible DoS caused by malformed signature decoding in Pure-Python ECDSA</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-2mrj-435v-c2cr</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ecdsa&lt;/p&gt;
&lt;p&gt;## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-pwfw-mgfj-7g3g. This link is maintained to preserve external references.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: ecdsa&lt;/p&gt;
&lt;p&gt;## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-pwfw-mgfj-7g3g. This link is maintained to preserve external references.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-2mrj-435v-c2cr</guid>
    </item>
  </channel>
</rss>
